Staff Threat Detection Engineer
Chainalysis
The Detection and Response Engineering (DaRE) team protects Chainalysis corporate assets and manages internal incident response. We reduce risk by building systems that detect and contain malicious activity while performing high-stakes digital forensics. Our mission is to ensure that as blockchain adoption grows, our own infrastructure remains resilient against evolving threats.
As a Staff Threat Detection Engineer, you are the technical lead for our corporate threat detection strategy. You design high-fidelity detections, lead proactive threat hunting, and perform critical risk assessments for both corporate and product engineering functions. This is a high-profile role where you will act as a subject matter expert (SME) for threat modeling, guiding security best practices across all corporate functions.
In this role, youβll:
- Lead Detection Strategy: Own the end-to-end roadmap for corporate threat detection, mapping coverage against frameworks like MITRE ATT&CK.
- Engineeer High-Fidelity Detections: Design and maintain scalable detection logic across SIEM, EDR, and cloud logging platforms (AWS/GCP).
- Conduct Threat Hunting: Plan and execute hypothesis-driven hunting campaigns to uncover novel TTPs and turn findings into durable controls.
- Perform Risk Modeling: Lead threat assessments and design reviews for new technology on-boarding and product design changes.
- Optimize Response: Partner with Incident Response to refine alert quality, automate triage playbooks, and reduce time-to-containment.
- Mentor & Influence: Provide technical leadership and mentorship to the DaRE team while influencing product teams to improve visibility and remediate gaps.
Weβre looking for candidates who have:
- 8+ years of experience in detection engineering, SOC, or incident response at scale.
- Deep expertise in building and tuning detections within SIEM, EDR, and log analytics platforms.
- Advanced proficiency in writing complex detection queries (e.g., KQL, S...
Share this job: